Operating a digital-asset business without secure fiat rails is not a structural inconvenience – it is an existential risk. Payment service providers and card acquirers sit at the intersection of two regulatory worlds: the legacy banking compliance regime and the newer, still-hardening virtual-asset supervisory perimeter. When those worlds collide inside a single contractual relationship, the compliance burden falls, disproportionately and immediately, on the crypto-side entity.
A PSP and acquiring agreement (a contract between a merchant or platform and a payment service provider or card acquirer granting access to fiat settlement and card acceptance infrastructure) is far more than a commercial arrangement. It is a live compliance instrument. Every clause on acceptable use, chargeback thresholds, reserve requirements and suspicious-activity reporting is a potential termination trigger – and in the digital-asset sector, those triggers fire more readily than in almost any other industry. Understanding the compliance burden embedded in that agreement is the first step to surviving a bank review, a derisking wave or a regulator-driven demand for enhanced due diligence.
This analysis examines the structure of PSP and acquiring compliance obligations as they apply to crypto exchanges, custodians, EMI (electronic money institution) applicants and token issuers, with particular attention to the cross-border tensions that arise when the entity, the payment rails and the end-user base sit in different regulatory environments.
Why PSP and Acquiring Agreements Are Compliance Instruments, Not Just Contracts
A PSP or acquiring agreement does not merely grant payment access – it imposes a second compliance layer on top of whatever licence the digital-asset business already holds. The agreement incorporates, by reference or by express clause, the acquirer's own acceptable use policy, card-scheme rules (Visa, Mastercard), applicable anti-money-laundering obligations under the relevant national regime and, increasingly, the acquirer's own internal risk appetite around virtual assets. The result is a contractual compliance regime that sits alongside – and sometimes conflicts with – the operator's own regulatory obligations.
In our cross-border practice, we see this dynamic most clearly when a VASP (virtual asset service provider) licensed in one jurisdiction attempts to onboard with a PSP or acquirer domiciled in another. The acquirer applies its home-country risk framework – which may be more restrictive than the VASP's own supervisory environment. A platform licensed under the MiCA CASP authorisation in an EU member state may find that a UK-based acquirer still applies pre-MiCA derisking heuristics, because the acquirer's internal policy has not yet caught up with the regulatory convergence. The licence alone does not unlock the rails.
What the agreement actually contains, beyond the commercial terms, typically includes: representations and warranties about the nature of the business and its customers; ongoing reporting obligations triggered by changes in business model, jurisdiction of operation or customer mix; thresholds for chargebacks and disputes, breach of which triggers suspension; requirements to maintain minimum reserve balances held by the acquirer; and unilateral termination rights exercisable on notice periods that, in practice, range from days to a few weeks. Each of these is a compliance obligation. Each is a potential point of failure.
What Triggers Termination or Suspension of a PSP or Acquiring Agreement?
Termination of a PSP or acquiring agreement is the most common and most damaging event in the fiat-rail lifecycle of a digital-asset business, and it is triggered far more often by compliance failures than by commercial disputes. The four dominant trigger categories are: regulatory change in the acquirer's home jurisdiction; reputational risk assessment by the acquirer's compliance team; breach of contractual thresholds; and card-scheme pressure applied directly to the acquirer.
Regulatory change is the least controllable trigger. When a national supervisor issues guidance tightening AML expectations for businesses with virtual-asset exposure, acquirers frequently respond by conducting portfolio reviews. Businesses that were onboarded under a prior, more permissive regime find themselves subject to enhanced due diligence requests, and if they cannot satisfy those requests within the acquirer's timeline, termination follows. The FCA's financial-promotion rules for crypto assets, introduced progressively in the UK, prompted exactly this kind of portfolio review among UK-based payment firms, with the effect that operators serving UK users from non-UK entities faced disproportionate scrutiny.
Reputational risk assessment is subjective and largely non-appealable under standard agreement terms. Acquirers maintain internal watchlists and scoring models that weight factors including the operator's sector (exchange, OTC desk, stablecoin issuer), its jurisdictional footprint, its customer acquisition channels and any adverse media. A negative mention in a regulatory press release – even one that ends in no finding – can trigger a risk review that leads to termination. Operators in our practice who have experienced this describe it as opaque: a letter citing "business risk outside our risk appetite" with no elaboration.
Chargeback thresholds and reserve requirements are quantitative triggers. Card schemes set tolerance thresholds for chargeback rates, and acquirers pass those thresholds through to their merchants. Digital-asset exchanges, where customers occasionally dispute purchases of tokens after a price decline, are structurally exposed to elevated chargeback rates during market downturns. Reserve requirements – whereby the acquirer holds a rolling percentage of settlement funds – can become a liquidity stress event if the business is growing quickly or if the acquirer decides, unilaterally, to increase the reserve percentage.
For a scoped review of your PSP or acquiring agreement and the compliance obligations it imposes, contact OBOLUS at info@oboluslaw.com. The process above describes the standard risk profile. Your entity structure, user base and banking jurisdiction change the analysis materially.
How Does the Cross-Border Structure of a Digital-Asset Business Create Compliance Tension in PSP Agreements?
The cross-border structure of most digital-asset businesses is the single greatest source of compliance friction in PSP and acquiring relationships. The entity that holds the licence, the entity that signs the PSP agreement, the jurisdiction whose customers use the platform and the jurisdiction where settlement occurs are frequently four different places – and the compliance obligations that attach to each differ significantly.
Consider the common structure: a holding company in the BVI, an operating entity in Lithuania (under the Bank of Lithuania's VASP supervision, transitioning to the MiCA CASP regime), a payment account at a UK-regulated EMI and card acquiring through a Malta-based acquirer. The Lithuanian entity is the regulated VASP. The UK EMI applies FCA Money Laundering Regulations requirements to the account relationship. The Malta acquirer applies MFSA rules and, post-MiCA transition, will apply CASP-level expectations. Each layer has its own compliance expectations, and none of them is fully aligned with the others.
In practice, the mismatch appears in three ways. First, the acquirer may require the contracting entity to be the regulated entity – but the regulated entity may not be the entity that commercially operates the merchant relationship. Restructuring to satisfy this requirement takes time and may have tax consequences. Second, the acquirer's AML screening will flag jurisdictions that the VASP legitimately serves under its licence but that the acquirer treats as elevated-risk. Third, the acquirer's customer due diligence requirements for sub-merchants or payment facilitators may demand disclosures about the VASP's own customer base that the VASP's privacy obligations constrain.
We regularly advise clients on re-mapping their entity structure to align the contracting entity with the regulated entity and to choose the PSP relationship in a jurisdiction whose regulatory expectations most closely match the operator's own licence environment. This is not a guarantee of smooth onboarding – it is a risk-reduction step that reduces the surface area for compliance conflict.
What Does EMI Onboarding Actually Require for a Digital-Asset Business?
EMI onboarding for a digital-asset business is a structured due diligence process that looks, in form, like a bank account application but is, in substance, closer to a regulatory examination. A well-prepared operator treats it as such.
The EMI (a firm authorised to issue electronic money and provide payment services under the applicable payment services regime) is itself a regulated entity. It holds a licence from its home-country supervisor – the FCA in the UK, an NCA under the EU payment services framework, the MFSA in Malta. As a regulated firm, the EMI is subject to AML/CFT obligations and to its supervisor's expectations regarding the risk profile of its business customers. A VASP is, by definition, a high-risk customer category under the FATF Recommendations and under most national AML frameworks. The EMI therefore applies enhanced due diligence to VASP onboarding – and it is entitled to decline the relationship without giving a reason, even where the VASP holds a valid licence.
The documentation demands are substantial. EMIs typically require: the VASP's licence or registration certificate; its AML/KYC policy documentation; its risk appetite statement; its beneficial ownership structure down to the ultimate beneficial owner; historical transaction data or, for a new business, projected transaction volumes with a credible basis; evidence of the VASP's own customer due diligence procedures; and, increasingly, an audit or independent review of those procedures. Some EMIs in the UK and EU market now require the VASP to have completed at least one external AML audit before they will open an account.
The Travel Rule (the obligation, under FATF Recommendation 16 and its national implementations, to pass originator and beneficiary data with virtual asset transfers) has added a further layer of complexity. EMIs that also handle virtual-asset flows – or that provide rails to VASPs – need to assess whether the VASP has Travel Rule compliance in place. A VASP that cannot demonstrate a credible Travel Rule solution will not satisfy EMI onboarding requirements in any well-supervised jurisdiction.
In our practice, we map the compliance documentation package before the client approaches an EMI. A complete, well-structured submission reduces the review timeline and avoids the cycle of repeated information requests that erodes trust and, ultimately, leads to a polite decline.
Which PSP or Acquiring Structure Fits Which Operator Profile?
There is no single PSP or acquiring structure that suits every digital-asset business. The right approach turns on the operator's licence environment, customer geography, transaction profile and growth stage. The following decision matrix – in qualitative terms, because capital and fee thresholds vary and must be verified against current requirements – illustrates how different profiles lead to different structural choices.
Profile A – EU-licensed CASP, primarily retail exchange: This operator holds or is seeking a MiCA CASP authorisation through a member-state NCA. Its primary compliance need is a PSP and acquiring arrangement with a European counterpart that understands the MiCA framework and can accept the passporting logic. The preferred structure is an acquiring relationship with an EU-licensed acquirer whose own AML framework is aligned with the CASP's home NCA. The key risk is selecting an acquirer in a member state whose NCA has adopted a more restrictive MiCA implementation than the VASP's home state. Timeline to onboarding, assuming complete documentation, is typically a matter of weeks to a few months depending on the acquirer's queue and the complexity of the VASP's business model.
Profile B – Dubai-based exchange, international customer base: This operator holds a VARA licence in Dubai for mainland operations. Its international customer base, which may include EU, Asian and US-adjacent users, creates a compliance complexity that no single PSP can fully absorb. The structure that works in our experience is a combination of a UAE-based EMI relationship for regional settlement and a separate EMI or acquiring relationship in an additional jurisdiction for the international book. VARA's activity-based licence structure means the operator needs to confirm that its PSP/acquiring arrangements are consistent with the licensed activities – an acquiring arrangement for card payments requires that the card-acceptance activity is within the scope of the VARA authorisation. The key risk is the US-adjacent exposure: a VASP serving any US-linked customers through card rails will attract scrutiny from acquirers with US banking relationships, regardless of where the VASP is licensed.
Profile C – Early-stage token issuer, no current VASP licence: This operator is pre-licence and needs fiat rails for a token sale or an initial exchange listing. The compliance burden here is acute: the operator cannot represent to a PSP that it holds a VASP licence, and most mainstream acquirers will not take on a token issuance as a merchant category. The realistic path is an EMI relationship with a firm that has explicit experience in token-issuance-related payments, combined with a legal opinion on the token's classification under the applicable regime – demonstrating it is not a security that would require a separate authorisation. Timeline is indeterminate without a licence; the compliance documentation package must substitute, partially, for the licence itself.
What Are the Most Common Compliance Mistakes in PSP and Acquiring Relationships?
The compliance mistakes that end PSP and acquiring relationships for digital-asset businesses are, in our experience, almost always avoidable. They fall into four categories: misrepresentation at onboarding, failure to notify on material change, structural mismatch between the contracting entity and the regulated entity, and inadequate internal AML/KYC documentation.
Misrepresentation at onboarding is the most serious. It occurs when an operator, under pressure to secure fiat rails quickly, describes its business in terms that do not fully reflect the nature of its activities. An exchange that describes itself as a "payment platform" to avoid the crypto-category flag is misrepresenting its merchant category. When the acquirer's risk team subsequently identifies the nature of the business – through transaction analysis, media monitoring or regulatory correspondence – the termination that follows is immediate and potentially reported to the supervisor. In some jurisdictions, misrepresentation in a payment onboarding context has regulatory consequences beyond the commercial relationship.
Failure to notify on material change is a contractual compliance failure. PSP and acquiring agreements almost universally require the operator to notify the PSP of material changes to its business, including changes in the services offered, the jurisdictions served, the beneficial ownership structure and the regulatory status of the business. In our practice, we have seen operators expand their service offering – adding staking, lending or OTC desk functionality – without notifying their acquirer, on the basis that it was an organic growth step. The acquirer's view, when it discovers the expansion, is that the operator is now a materially different merchant from the one that was onboarded. Termination follows.
Structural mismatch between the contracting entity and the regulated entity is a subtler problem. Where the entity that signed the PSP agreement is not the same entity that holds the licence, the acquirer's compliance framework cannot properly anchor to the regulated status of the business. Resolving this requires either a novation of the agreement to the licensed entity or a restructuring of the group that places the licensed entity in the contracting position.
Inadequate internal AML/KYC documentation means that when the acquirer exercises its contractual right to audit the operator's compliance procedures, the operator cannot produce a documented, current AML policy that satisfies the acquirer's standards. This is common at growth-stage businesses where the compliance build has lagged the commercial build. The fix is structural – not a matter of quickly drafting a policy to satisfy an audit – and it takes longer than most operators expect.
A recent matter illustrates the compounding effect. A custody business in a mid-tier EU jurisdiction had onboarded with an EMI two years earlier, under a prior VASP registration regime. As the Bank of Lithuania and equivalent NCAs moved to apply MiCA-transition enhanced due diligence, the EMI conducted a portfolio review. The custody business could not produce an updated AML policy that addressed the MiCA CASPs obligations, and its Travel Rule solution was not yet operational. The EMI issued a 30-day termination notice. We were engaged to stabilise the relationship: we produced a gap analysis, a remediation plan and a transition timeline, and we opened a parallel onboarding conversation with a second EMI. The account was preserved through the remediation, and the second EMI relationship provided a redundancy that the business had lacked for its first two years of operation.
Is a Single Offshore Licence Enough to Manage the PSP Compliance Burden Globally?
A common assumption in the market is that a single offshore VASP licence – in the BVI, Cayman Islands or a similar jurisdiction – resolves the compliance burden for a globally operating exchange or custodian. It does not. The licence resolves the regulatory status question in the jurisdiction that issued it. It does not resolve the compliance expectations of PSPs and acquirers in the jurisdictions where the operator's customers are located, where settlement occurs or where the PSP is itself regulated.
The BVI FSC's VASP Act 2022 and CIMA's virtual-asset regime under the Cayman VASP Act are legitimate regulatory frameworks. They impose real obligations on registered operators. But a UK-regulated EMI onboarding a BVI VASP will apply FCA AML standards to that relationship – and those standards require the EMI to understand the BVI VASP's own customer base, its AML procedures and its compliance with the Travel Rule. The BVI registration certificate is evidence of regulatory status in the BVI. It is not a substitute for the compliance documentation the UK EMI needs to satisfy its own supervisor.
The practical consequence is that an operator licensed only in an offshore jurisdiction, and seeking PSP or acquiring relationships in regulated financial hubs – the EU, the UK, Singapore, Hong Kong – will need to build a compliance stack that meets the expectations of each PSP's home regulator. That compliance stack is substantially identical to the compliance stack required for a licence in one of those hubs. At a certain scale of business, the incremental cost of obtaining a second, hub-jurisdiction licence becomes lower than the ongoing cost of repeatedly satisfying PSP due diligence from an offshore-only base.
We map that cost-benefit analysis for clients deciding where to licence. The output is a licence, banking and compliance structure that is designed around the operator's actual user base and payment flows – not around the easiest available registration.
If a prior PSP application stalled or an account was closed, a second read of your structure can surface the root cause and the route to resolution. Write to OBOLUS at info@oboluslaw.com.
How Does the Travel Rule Interact with PSP and Acquiring Compliance?
The Travel Rule intersects PSP and acquiring compliance at two points: as an onboarding requirement and as an ongoing operational obligation that acquirers and EMIs expect their VASP clients to satisfy. Its interaction with fiat rails is less obvious than its interaction with on-chain transfers – but it is increasingly significant.
Under FATF Recommendation 16 and its national implementations (including under the applicable VASP provisions in the EU, UK, Singapore and other leading hubs), a VASP must collect and transmit originator and beneficiary data when conducting virtual-asset transfers above the applicable threshold. The threshold varies by jurisdiction and must be verified against current legislation in each relevant market. What does not vary is the principle: the Travel Rule applies to the virtual-asset transfer, not to the fiat leg. But PSPs and acquirers increasingly require evidence that the VASP has a Travel Rule compliance solution in place before they will maintain a payment relationship.
The reason is straightforward. An acquirer processing card deposits for a VASP that later turns out to have no Travel Rule compliance – and that is subsequently subject to regulatory action – faces reputational and potentially supervisory consequences of its own. Acquirers and EMIs have begun including Travel Rule compliance as a due diligence criterion, not just at onboarding but in annual reviews. Operators without a deployed Travel Rule solution are increasingly unable to pass those reviews.
The operational implication for the PSP agreement is that the VASP needs to be able to demonstrate – not just assert – Travel Rule compliance. That means a deployed technology solution, an internal policy governing its application and records showing it has been applied to actual transfers. In our practice, we see the gap between "we have a Travel Rule solution" (a vendor contract) and "we have Travel Rule compliance" (deployed, tested, audited) creating significant friction in EMI and acquirer reviews.
Self-Assessment: Is Your Business Ready for PSP and Acquiring Due Diligence?
A digital-asset business that can answer yes to each of the following questions is materially better positioned to survive PSP and acquiring due diligence than one that cannot. These are the questions that acquirers and EMIs ask – some explicitly in their onboarding questionnaire, others implicitly through the documentation they request.
Does the entity that will sign the PSP agreement hold, or is it in the process of obtaining, a VASP licence or registration in a jurisdiction whose regulatory framework the acquirer recognizes? Is the beneficial ownership structure of the business documented, current and verifiable against public registers where applicable? Is there a documented AML/KYC policy that has been reviewed and updated within the past twelve months and that addresses, specifically, the business's virtual-asset activities? Has the business undergone an independent AML audit by a firm with recognized expertise in virtual-asset compliance? Is a Travel Rule compliance solution deployed and operational? Can the business provide at least twelve months of transaction data – or, if pre-revenue, a credible projected transaction profile with stated assumptions? Is the business's merchant category description accurate, complete and not materially different from its actual activities? Does the business have a change-notification process that will flag material changes in its business to the PSP before, not after, they occur?
If the answer to any of these is no, that is the point at which to engage counsel and remediate before approaching an acquirer or EMI. The cost of a failed onboarding – in time, in reputational signal to the next potential PSP and in management distraction – is substantially higher than the cost of pre-application preparation.
Related at OBOLUS
- Banking, Payments and EMI Onboarding – how we structure fiat-rail and payment account access for digital-asset businesses
- Fiat On/Off-Ramp Banking in the United Kingdom – the FCA regulatory environment and banking options for UK-connected operations
- Legal Counsel for Digital-Asset Custodians – compliance, licensing and banking structuring for custody businesses
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily for three reasons: the operator's business model is categorized as high-risk under the bank's internal AML framework; the operator cannot produce compliance documentation that satisfies the bank's enhanced due diligence requirements; or the bank's own regulator has issued guidance that effectively narrows the risk appetite for virtual-asset exposure. A valid VASP licence reduces but does not eliminate this risk. Banks assess the compliance infrastructure of the business, not only its regulatory status. Operators with documented AML policies, Travel Rule solutions and clean beneficial ownership structures are materially less likely to face closure.
How can a VASP onboard with an EMI?
A VASP can onboard with an EMI by preparing a complete compliance documentation package before making the approach. That package typically includes the VASP's licence or registration certificate, a current AML/KYC policy, a beneficial ownership structure to the ultimate beneficial owner level, evidence of a deployed Travel Rule compliance solution, and historical or projected transaction data. Some EMIs also require an independent AML audit report. The onboarding process is a due diligence exercise, not simply a commercial negotiation. Operators who treat it as such – and who approach EMIs with a track record of regulatory compliance – achieve significantly better outcomes.
What does client-money safeguarding require?
Client-money safeguarding requires that an operator – or the EMI holding funds on its behalf – segregates customer funds from the firm's own funds and holds them in a manner that protects customers in an insolvency. Under most applicable payment services regimes, safeguarding can be achieved either through a designated safeguarding account at a regulated credit institution or through a qualifying insurance or guarantee arrangement. The specific requirements, including the calculation method for the amount to be safeguarded and the frequency of reconciliation, vary by jurisdiction and must be verified against current legislation in the relevant market. Non-compliance with safeguarding obligations is a regulatory breach that acquirers and EMIs treat as a termination trigger.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – reducing the risk of failed onboarding, frozen rails and enforcement exposure. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in PSP and EMI onboarding compliance, AML frameworks and cross-border payment structuring for virtual-asset service providers.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.